Cortex C2 is a Open source Linux C2 inspired by the void link C2 framework
☆44May 29, 2026Updated 2 months ago
Alternatives and similar repositories for cortex-c2
Users that are interested in cortex-c2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A PoC Cobalt Strike UDRL written in Rust☆33Jun 20, 2026Updated last month
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 3 months ago
- Rust Based PE & Shellcode Packer☆42Dec 28, 2025Updated 7 months ago
- Step through PE functions or shellcode instruction-by-instruction (amd64)☆42May 4, 2026Updated 3 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆88Apr 8, 2026Updated 3 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆29Jul 6, 2026Updated 3 weeks ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Jul 23, 2026Updated last week
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last week
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆145Apr 22, 2026Updated 3 months ago
- A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself☆101Apr 9, 2026Updated 3 months ago
- Cobalt Strike BOF to obtain location data☆29Jul 4, 2026Updated 3 weeks ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆92Jun 24, 2026Updated last month
- ☆58Jul 12, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 2 months ago
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated 2 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆114Jun 30, 2026Updated last month
- Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.☆75Jul 26, 2026Updated last week
- windows api bug☆38May 24, 2026Updated 2 months ago
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated last week
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- A Telegram bot interface for the Adaptix C2 Teamserver. Manage agents, execute commands, handle credentials, view tasks, and download fil…☆21Mar 9, 2026Updated 4 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆136Jul 20, 2026Updated 2 weeks ago
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- Thermal pocket printer - BLE protocol reverse engineering, Python CLI, and web GUI☆15May 4, 2026Updated 2 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆21Jul 24, 2026Updated last week
- Another BYOVD process killer. works on all EDR's. fully signed.☆288May 19, 2026Updated 2 months ago
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆109Jul 20, 2026Updated 2 weeks ago
- Proof of concept to detect module stomping detection by looking for modified .pdata sections.☆41Jun 11, 2026Updated last month
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Jul 5, 2026Updated 3 weeks ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- M365 Conditional Access Policy Bypass OST (Offensive Tooling)☆45Apr 22, 2026Updated 3 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆76Jun 2, 2025Updated last year
- A rust implementation of HackBrowserData☆18Oct 1, 2025Updated 10 months ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆84Jan 26, 2026Updated 6 months ago
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆37Jan 17, 2026Updated 6 months ago
- ☆68Jul 14, 2026Updated 2 weeks ago